Source description
About the role
As a ServiceNow GRC / IRM Architect, you will be the senior technical authority responsible for designing, implementing, and governing scalable enterprise-grade solutions within the ServiceNow Integrated Risk Management (IRM) and Governance Risk & Compliance (GRC) ecosystem. Your role involves protecting the business, ensuring compliance with global regulators, and providing real-time risk intelligence to leadership. You will collaborate with Risk, Audit, Legal, Privacy, and CISO functions to automate and modernize the GRC program, incorporating AI-driven risk capabilities. Key Responsibilities: - Platform Architecture & Design: - Lead end-to-end design and delivery across various modules such as Policy & Compliance, Risk Management, Audit Management, Vendor Risk, BCM, and AI Control Tower. - Define and maintain the enterprise IRM architecture and technology roadmap aligned with regulatory strategy and risk appetite. - Ensure solutions are scalable, secure, compliant, and aligned with ServiceNow platform best practices. - Drive OOTB adoption and enforce architectural governance throughout the implementation lifecycle. - Risk & Compliance Programme Design: - Design risk frameworks, control libraries, risk appetite statements, and automated control testing workflows. - Architect third-party/vendor risk management programs, assessment workflows, scorecards, and due diligence processes. - Configure and govern the AI Control Tower module for AI model risk management, AI inventory, and AI governance controls. - Own the BCM/DR module blueprint to integrate risk assessment workflows with operational recovery planning. - Integration & Technical Delivery: - Define integration strategies with tools like SIEM/SOAR, vulnerability management platforms, ERP systems, and identity platforms. - Architect integrations with ServiceNow SecOps suite, Vulnerability Response, and Security Incident Response for a unified cyber-risk posture. - Ensure control-to-asset accuracy via CMDB/CSDM alignment and service mapping. - Stakeholder Engagement & Leadership: - Lead GRC workshops, design sessions, and architecture reviews with Audit, Legal, Privacy, Risk, and CISO stakeholders. - Act as a trusted advisor to senior client and executive stakeholders on GRC and risk transformation initiatives. - Mentor GRC developers and consultants, conduct code and design reviews, and set development standards. Qualifications: - Education: - Bachelor's degree in Information Technology, Computer Science, Information Security, Risk Management, or related field (required). - Master's degree (MBA, MSc Cybersecurity, or MSc Risk Management) strongly preferred for Principal-level roles. - Experience: - 10-14 years of total professional experience in IT with a minimum of 5 years of hands-on ServiceNow IRM/GRC implementation experience. - Prior experience in regulated industries such as BFSI, Healthcare, Defence, Energy, and Utilities is advantageous. - Experience migrating from legacy GRC platforms is a plus. This role requires expertise in ServiceNow IRM/GRC modules, platform scripting, integrations, and related certifications. Additionally, you should possess behavioral competencies such as strategic thinking, stakeholder influence, technical leadership, communication, problem-solving, and continuous learning to excel in this position. Please note that the JD does not contain any additional company details. As a ServiceNow GRC / IRM Architect, you will be the senior technical authority responsible for designing, implementing, and governing scalable enterprise-grade solutions within the ServiceNow Integrated Risk Management (IRM) and Governance Risk & Compliance (GRC) ecosystem. Your role involves protecting the business, ensuring compliance with global regulators, and providing real-time risk intelligence to leadership. You will collaborate with Risk, Audit, Legal, Privacy, and CISO functions to automate and modernize the GRC program, incorporating AI-driven risk capabilities. Key Responsibilities: - Platform Architecture & Design: - Lead end-to-end design and delivery across various modules such as Policy & Compliance, Risk Management, Audit Management, Vendor Risk, BCM, and AI Control Tower. - Define and maintain the enterprise IRM architecture and technology roadmap aligned with regulatory strategy and risk appetite. - Ensure solutions are scalable, secure, compliant, and aligned with ServiceNow platform best practices. - Drive OOTB adoption and enforce architectural governance throughout the implementation lifecycle. - Risk & Compliance Programme Design: - Design risk frameworks, control libraries, risk appetite statements, and automated control testing workflows. - Architect third-party/vendor risk management programs, assessment workflows, scorecards, and due diligence processes. - Configure and govern the AI Control Tower module for AI model ris
More at NewVison